CurveBall (CVE-2020-0601)? Complexity.
BigSig (CVE-2021-43527)? Memory safety.
Log4Shell (CVE-2021-44228)? Complexity.
BlueKeep (CVE-2019-0708)? Memory safety.
Heartbleed looks like memory safety, but it's actually complexity.
CurveBall (CVE-2020-0601)? Complexity.
BigSig (CVE-2021-43527)? Memory safety.
Log4Shell (CVE-2021-44228)? Complexity.
BlueKeep (CVE-2019-0708)? Memory safety.
Heartbleed looks like memory safety, but it's actually complexity.
But it happened.
@github.com asked me to share the story as I lived it, for the benefit of users of #opensource. How could I say no?
I hope it helps build a more secure future.
No more Log4Shell.
#java
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.
Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...
But it happened.
@github.com asked me to share the story as I lived it, for the benefit of users of #opensource. How could I say no?
I hope it helps build a more secure future.
No more Log4Shell.
#java
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.
Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...
One small library affecting billions of systems.
Log4Shell was the biggest security vulnerability of all time.
Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...
And the internet.
Watch the full interview about the biggest security vulnerability of all time 👉 https://github.blog/open-source/inside-the-breach-that-broke-the-internet-the-untold-story-of-log4shell/?utm_source=social&utm_medium=social&utm_campaign=minecraft
And the internet.
Watch the full interview about the biggest security vulnerability of all time 👉 https://github.blog/open-source/inside-the-breach-that-broke-the-internet-the-untold-story-of-log4shell/?utm_source=social&utm_medium=social&utm_campaign=minecraft
Excluding codegen bugs (like the one in wasmtime), since unfortunately the safety guarantees of Rust only extend to actual rust code, not code generated by rust code.
MOVEit and Log4Shell *still* in the top 15.
https://www.cisa.gov/sites/default/files/2024-11/aa24-317a-2023-top-routinely-exploited-vulnerabilities.pdf
MOVEit and Log4Shell *still* in the top 15.
https://www.cisa.gov/sites/default/files/2024-11/aa24-317a-2023-top-routinely-exploited-vulnerabilities.pdf
We'll go first: Remote code execution.
https://github.blog/open-source/inside-the-breach-that-broke-the-internet-the-untold-story-of-log4shell/
We'll go first: Remote code execution.
https://github.blog/open-source/inside-the-breach-that-broke-the-internet-the-untold-story-of-log4shell/
podcasts.apple.com/de/podcast/f...
#java #log4j #log4shell
podcasts.apple.com/de/podcast/f...
#java #log4j #log4shell
github.blog/open-source/...
github.blog/open-source/...
Additional disclosures can be frustrating, but they are generally a sign of a healthy response cycle.
Additional disclosures can be frustrating, but they are generally a sign of a healthy response cycle.
In this episode of The GitHub Podcast, we talk to Christian Grobmeier about the aftermath of Log4Shell and what it means for the future of open source funding. the-github-podcast.simplecast.com/episodes/fro...
In this episode of The GitHub Podcast, we talk to Christian Grobmeier about the aftermath of Log4Shell and what it means for the future of open source funding. the-github-podcast.simplecast.com/episodes/fro...